Policy & Regulation — Page 7

Android's Identity Wall Goes Up Sept. 30, 2026 — Starting With Four Countries
Brazil, Indonesia, Singapore and Thailand are the first markets where unverified developers lose the right to install apps on certified Android devices, sideload or not.

When Legacy Infrastructure Becomes the Soft Underbelly of Your AI Agent Stack
Governance frameworks like NIST AI RMF and the EU AI Act assume the pipes under the model are secure. They often aren't.

CSIS Got a Warrant to Reach Into Canadian Routers and Kill Two Botnets
A Federal Court ruling unsealed June 15 is the first public use of CSIS threat-reduction warrant powers against infected infrastructure on Canadian soil.

Macron Pushes Wealthy Democracies Toward a Unified AI Regulatory Front
The French president wants the G7 crowd to stop freelancing on AI governance and start coordinating. Whether that translates into anything enforceable is a different question entirely.

Operation Endgame Sweep Takes Down SocGholish Loader Infrastructure
Dutch-led coalition disrupts servers and remediates 14,971 compromised WordPress sites, in the latest tranche of the multinational takedown effort.

Mastra npm Namespace Hit: 145 Packages Tampered After Contributor Account Hijack
Researchers tracking the 'easy-day-js' supply chain incident say a single compromised maintainer account was sufficient to push malicious versions across the @mastra/* registry footprint.

Accenture Moves to Acquire Dragos, runZero, and NetRise in $4.1 Billion OT Security Consolidation
The deal values Dragos alone at $3.25 billion. runZero and NetRise would fold under the Dragos umbrella post-close.

India Tells Court Telegram Couldn't Detect Exam-Leak Channels Before Block
Government says it warned Telegram two weeks before pulling the plug. Telegram says the ban is unlawful and that it cooperated.

PCI DSS 4.0.1 Drags Checkout Scripts Into Scope, and Most Merchants Aren't Ready
Independent QSA assessment puts Reflectiz against the new client-side rules. The verdict: the script soup running on your payment page is now an auditable surface.

Six Security Leaders Who Changed Jobs in Early 2026
From Air Force intelligence to frontier AI, the CISO hiring market is moving. Here is who landed where — and what the patterns suggest.

Google to Harvest UK and EU IP Addresses for Ad Targeting Starting August 2026
The same signal Google once branded a privacy red flag becomes a measurement tool, just as the ICO sharpens its consent rules.

Tailscale and OpenSSH Became a Junior Operator's Back Door After His Havoc C2 Went Dark
An intrusion at a small French auto-sector firm shows how commodity remote-access tooling defeats the assumption that killing the C2 ends the incident.

Estonia Wants to Give AI Agents Government-Issued IDs — With Spelled-Out Permission Scopes
The Baltic nation's AI Council is proposing state-backed digital identities for AI agents, defining exactly what they're allowed to do before they touch your data or your bank account.

India Pulls Telegram Offline Until June 22 — and the Block Spilled Into the UAE
New Delhi cites leaked exam papers circulating in Telegram channels. Pavel Durov says Reliance Jio went further, hijacking BGP routes that broke the app well outside India's borders.

CISA Sets Three-Day Patch Deadline for Actively Exploited LiteSpeed cPanel Plugin Flaw
CVE-2026-54420 lands on the KEV catalog, triggering a BOD 22-01 remediation clock for federal civilian agencies.